NSE4 Security Profiles Practice Question
An administrator needs to block users from uploading files containing credit card numbers to external websites. Which TWO actions must be configured? (Choose two.)
⚠ Common exam trap
The trap here is that candidates often forget that DLP requires SSL inspection to see the content of encrypted traffic, and mistakenly think a DLP profile alone is sufficient to block credit card numbers in HTTPS uploads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable SSL deep inspection on the firewall policy
SSL deep inspection is required to decrypt HTTPS traffic so the firewall can inspect the content of encrypted uploads for sensitive data like credit card numbers. Without decryption, the DLP profile cannot see the payload of encrypted sessions, rendering the DLP sensor ineffective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply an antivirus profile to the policy
Why it's wrong here
Antivirus profiles are designed to detect and neutralize malware based on signature or behavioral analysis; they do not parse file payloads for sensitive data patterns such as credit card numbers. Even if a file containing a credit card number is uploaded, antivirus will allow it unless it matches a known malicious signature. Furthermore, without SSL deep inspection, antivirus cannot even inspect HTTPS-encrypted uploads, leaving a critical blind spot.
- ✓
Enable SSL deep inspection on the firewall policy
Why this is correct
Enabling SSL deep inspection on the firewall policy is a prerequisite for any content-aware inspection of HTTPS traffic. It forces the firewall to decrypt outbound SSL/TLS sessions so that security profiles, including DLP, can examine the actual file contents being uploaded. By itself it does not block uploads; rather, it provides the visibility needed for a DLP sensor to detect and enforce a block on credit card data. This step is essential because without decryption, the firewall would merely see encrypted bytes and cannot apply data-loss prevention rules.
- ✓
Create a DLP profile with a credit card number sensor set to block
Why this is correct
A DLP profile with a credit card number sensor is the direct enforcement mechanism: it uses pattern matching and Luhn algorithm validation to identify credit card numbers in file content and can apply a block action to prevent the upload. This sensor can be configured to trigger on multiple occurrences or specific formats, and it works in conjunction with SSL deep inspection to inspect decrypted payloads. Once triggered, the firewall blocks the session or files, thus meeting the data protection requirement.
- ✗
Configure application control to block file transfer applications
Why it's wrong here
Application control focuses on identifying and controlling the applications running over the network, not on inspecting the content within those applications' traffic. Blocking file transfer applications would only prevent uploads via known application signatures, but users could still upload sensitive data through allowed applications like web browsers or Microsoft Teams. It also does not detect whether a file contains a credit card number—it simply stops the application category, which is an overbroad and ineffective control for data loss prevention.
- ✗
Use a web filter to block all upload websites
Why it's wrong here
Using a web filter to block all upload websites is an overbroad action that would likely break legitimate functionality, as many websites allow file uploads for valid business purposes (e.g., email attachments, document sharing). Web filtering categorizes entire domains or URLs, so it cannot differentiate between benign uploads and those containing sensitive data. Additionally, this approach fails to address uploads over non-HTTP protocols such as FTP or SMTP, and it would require maintaining a massive block list that is both incomplete and disruptive.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.